Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk, Treasury & Financial Control
1Risk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
2Enterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
3Risk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
4Credit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
5Market Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
6Liquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
7Operational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
8Risk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
9Treasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
10Financial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
11Operational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Data Governance in Risk: Ownership, Stewardship and Trust

Data governance decides who is accountable for a number being right before anybody uses it. The arrangement names an owner in the business for each element, a steward who maintains it, and a written statement of what the element means, where it comes from, what it may contain and what happens when it is absent. At the invented Vindhya Commercial Bank Limited, 42 of 147 risk data elements carry all eight.

Everything in this guide rests on one reframing, and taking it now makes the rest fall into place. Most readers arrive believing data quality is a technical problem about systems: a better platform, a tighter interface, a cleaner load. It is not. Every one of the eight attributes below is a sentence somebody has to write and somebody has to be accountable for, and no system produces a single one of them. A source system can report what a field contains. A source system cannot say what the field means, who decided that, what report line the field feeds, or what everybody downstream should do on the morning it arrives empty. Every one of those is a human act, and a committee reading a number is trusting all of them whether or not it knows they happened.

What is data governance protecting, if it is not protecting the data?

Start with what is actually at stake, and it is not the data. Data governanceThe arrangement that decides who is accountable for a number being right, and what must be written down before anybody relies on it. in a risk function protects the trust a decision maker places in a number they did not compute and cannot check. Trust is the whole asset. A committee member reading a monthly risk report is not going to open a source system. The committee member is going to read a figure, believe it, and take a decision that costs money. Everything between the source and that moment is a chain of promises, and data governance makes each promise explicit and puts a name against it.

The everyday version is closer than it looks. A household runs on a small set of numbers: what comes in each month, the rent, the loan instalment, what is left. Somebody in that household holds each of those numbers in their head. The questions this guide asks of a bank apply just as well to that household. Does the phrase what comes in mean take-home or gross, before or after the reimbursement that sometimes arrives? Where does the figure come from, a payslip or a memory? Who updates it when it changes? And what happens in the month the second income does not arrive at all? Most households have never answered the fourth question, and that is precisely the month the budget stops working. The gap in a household budget and the gap in a bank's risk data set are the same gap: nobody wrote down what to do when the number is not there.

So the object being protected is trust, and trust is built in a chain. Six separate human acts stand between a source system holding a value and a committee acting on a number. Somebody agreed what the element means. Somebody named where it comes from. Somebody accepted accountability for it being right. Somebody was appointed to maintain it. Somebody thought about the morning it does not arrive and wrote down what should happen. And somebody traced the path from the source to the report line. Miss any one and the number still appears, in the same font, on the same day of the month, looking exactly as trustworthy as it did before.

SIX HUMAN ACTS BETWEEN A SOURCE SYSTEM AND A COMMITTEE PAPER Not one of the six is produced by any system, and a number arrives looking identical whether they happened or not. A SOURCE SYSTEM HOLDS A VALUE. THAT IS THE WHOLE OF WHAT IT CAN REPORT. 1 SOMEBODY AGREED what the element means, so two people arguing mean the same thing 2 SOMEBODY NAMED the place the value comes from, so it can be traced and not assumed 3 SOMEBODY ACCEPTED accountability for the element being right, by name, in the business 4 SOMEBODY APPOINTED the person who maintains it and chases it when a check fails 5 SOMEBODY THOUGHT about the morning it does not arrive, and wrote down what happens 6 SOMEBODY TRACED the path from the source to the report line, so it can be checked A COMMITTEE READS THE NUMBER AND TAKES A DECISION THAT COSTS MONEY.
Trust in a reported number is assembled from six separate human acts, and the fifth of them, writing down what should happen on the morning a value does not arrive, is the one this bank left out of most of its record.
Try it out

A colleague argues that data quality is a technology problem and belongs with whoever runs the systems. What is the sentence that corrects them?

The Data Owner: what is one person actually accountable for?

The first named job is the owner, and the word does more work than it looks. A data ownerThe person accountable for a data element being right, sitting in the business that uses it rather than in the technology that stores it. is the person accountable for a data elementOne defined item of data, such as a collateral valuation or an internal grade, that feeds a report line. being right. Not for storing it, not for moving it, not for the interface that carries it. For it being right. And accountability here has the ordinary meaning it has everywhere else: if the element is wrong, this is the person who has to explain it, and nobody gets to say they assumed somebody else was watching.

The owner sits inside the business using the number, and putting them anywhere else quietly destroys the role. The reason is not political, it is practical. Deciding what a collateral valuation means, whether it is the assessed value or the value after a charge, whether it includes the second charge or excludes it, and how old a valuation may be before it stops counting, is a set of business judgements. The questions are not about storage, so somebody who administers a store of values cannot make them. Each one is about what the business intends the number to represent. Asking a technologist to define a business term yields either a definition of the field or a definition somebody else gave them, and in both cases the accountability has evaporated on the way.

The household test again. In a household, the person accountable for what the phrase monthly income means is whoever earns and spends it, not the bank that shows the credit on a statement. The statement can confirm that a number arrived. The statement cannot settle whether the annual bonus counts, whether the reimbursement is income or a repayment, or whether the rent from the second property is dependable enough to plan around. All three are decisions, and the person who has to live with the consequence is the one who has to make them. Moving that decision to the record keeper produces a very tidy record of a number that means nothing in particular.

What does an owner actually decide, and who do they answer to?

Accountability with nothing to decide is a title. An owner decides four things, and each of the four turns into a line in a written record that other people can read without asking anybody.

The first decision is the definition, the sentence that says what an element covers and what it excludes. The second is the permitted values and the format, and a stated range is what makes a wrong value detectable rather than merely unusual. The third is the refresh frequencyHow often an element is expected to be updated, which is what makes it possible to notice that it has not been., the statement of how often the value should be renewed, and this third decision is quietly powerful: without an expected frequency there is no such thing as late, and without late there is no such thing as stale dataA value that is present, looks normal and is older than it should be, which is harder to notice than a value that is missing.. And they decide the rule for absenceThe written statement of what should happen when a value does not arrive, without which nothing happens., the statement of what should happen when the value does not arrive at all. Hold on to that fourth one. Everything below turns on it.

In this invented bank, Zoya Kalbagh is the data owner for the risk data set as a whole, and 103 of the 147 elements carry a named owner beneath her. The two-level structure is worth pausing on: it is the usual one, and it has a usual failure. A single accountable name at the top is what stops the set falling between functions. Named owners underneath are what make the accountability specific enough to act on. An owner for the set and no owners for the elements leaves one person accountable for 147 things they cannot individually see, and that is a way of having nobody accountable for any of them. Vindhya Commercial Bank Limited has both, on 103 elements. On the other 44 it has only the first.

Who does an owner answer to? In the ordinary case, the committee that receives the report the element feeds. The committee carries the consequence of the number being wrong. Notice what this bank's own record does not contain: it names an owner for the risk data set and does not record any committee receiving a measure of how complete that set is. The counts in this guide exist. Nothing in the record says who reads them. A measure with no reader is not a scandal and it is extremely common, and it is the reason a completeness measure can sit at 28.6 per cent for a long time without anybody being uncomfortable.

The Data Steward: who keeps the element alive between month ends?

The second named job is the steward, and the distinction from the owner is the single most useful idea in this guide for anybody who has to build one of these arrangements. A data stewardThe person who maintains a data element day to day, runs its checks and chases its breaks, usually sitting in the source system. maintains the element day to day. The steward runs the checks that test whether today's value looks like a value should look. The steward chases the breaks when a check fails. The steward fixes the record when it is wrong, knows which upstream team to call at seven in the morning, and holds the operational detail that nobody in a business function will ever carry in their head.

The steward sits where the value is produced, and that placement is the whole reason the job exists. Somebody in a business function can define what a collateral valuation means. But nobody in a business function can notice, on a Tuesday, that a file arrived at the usual time with the usual row count and the usual formatting and yesterday's values inside it. Yesterday's values in a normal-looking file are visible only to somebody close enough to the production of the value to know what normal looks like. So the steward sits in the source system, and in this bank the stewards sit across the source systems rather than inside the risk function. The risk function therefore cannot fix a data problem by working harder at its own end.

Two things follow that people get wrong. First, the steward is not junior to the owner in importance, only different in accountability: the owner answers for the element being right, the steward answers for having done the maintenance. Second, a steward with no owner is a person maintaining a value nobody has defined, and no job in this whole arrangement is more demoralising. Forty four elements in this bank currently offer exactly that.

Derivatives Foundation Bootcamp — Fin Maverick

Owner or steward: what breaks when one person is handed both jobs?

The two jobs get collapsed constantly, usually with the best intentions and usually because one person seems to know the most about the element. Here they are apart.

 The data ownerThe data steward
Sits inThe business using the numberThe source system where the value is produced
Accountable forThe element being rightThe element being maintained
DecidesThe meaning, the permitted values, the refresh frequency, the rule for absenceNothing about meaning. Everything about the daily running
Does dailyNothing. This is not a maintenance jobRuns the checks, chases the breaks, fixes the record
Answers forA wrong number reaching a committeeA check that was not run or a break that was not chased
In this invented bankZoya Kalbagh for the set, with 103 of 147 elements carrying a named owner beneath herNamed individually in the record for each element, sitting across the source systems

Now the failure mode. Maintenance has a queue and a deadline every single day and accountability has neither, so give both jobs to one person and the accountability quietly becomes a maintenance task. The daily work always wins. Six months later the checks are running beautifully, the breaks are chased inside an hour, and nobody has looked at whether the definition still matches what the business means. Checking the definition was never on anybody's list for today. Collapsing the two jobs does not produce one person doing both, it produces one person doing the urgent one.

TWO JOBS, TWO ACCOUNTABILITIES, TWO PARTS OF THE BANK One answers for the number being right. The other answers for the maintenance having been done. THE DATA OWNER SITS IN The business that uses the number, never the store ACCOUNTABLE FOR The element being right, by name DECIDES The meaning, the permitted values, the refresh frequency, and what happens when it is absent IN THIS INVENTED BANK Zoya Kalbagh is data owner for the risk data set, and 103 of the 147 elements carry a named owner beneath her. The other 44 carry nobody at all. THE DATA STEWARD SITS IN The source system where the value is produced ACCOUNTABLE FOR The element being maintained, day by day DECIDES Nothing about meaning. Everything about the running: the checks, the breaks, the fixes IN THIS INVENTED BANK The stewards sit across the source systems and not in the risk function, which is why the risk function cannot fix a feed by working harder. COLLAPSE THE TWO AND THE DAILY WORK WINS: ACCOUNTABILITY BECOMES A MAINTENANCE TASK.
Set the two jobs side by side and the reason they cannot be held by one person becomes obvious: one of them has a deadline every single day and the other has none, so the undated one stops happening.
Try it out

Which of the two sits in the business, and what exactly are they accountable for?

What eight things should an element carry before anybody relies on it?

Here is the working record, and it is not long. The bank's data dictionaryThe written record of what each element means, where it comes from, what it may contain and what to do when it is absent. asks eight questions of every risk data element and numbers them T1 to T8. Eight lines on one element. Any institution can write a different eight, and the count is this bank's own choice rather than anybody's standard, but the shape is what matters: each line exists because somebody downstream will one day ask exactly that question and needs an answer without calling a meeting.

 The attributeWhat goes wrong without it
T1The definitionTwo people report the same element and mean different things, and neither is wrong
T2The source systemNobody can go back to where the value came from, so every dispute becomes an opinion
T3The named data ownerNo name answers for the element being right, so the wrong number has no address
T4The named data stewardNo name runs the checks or chases the break, so a failure has to be noticed by luck
T5Permitted values and formatA wrong value looks merely unusual instead of failing a test, so nothing rejects it
T6The refresh frequencyThere is no such thing as late, so there is no such thing as stale
T7What happens when the value is absentNothing is defined to happen on the morning it does not arrive, so nothing happens
T8The lineage to the report lineThe number is present and not checkable, which is the state that survives longest

Read the eight in order and notice that seven of them describe the value and only one describes its absence. T1 through T6 and T8 are all statements about a value that is there: what it means, where it came from, who answers for it, who maintains it, what it may contain, how often it renews, and how it reaches the report. T7 is the only line in the list that describes a day when the value is not there at all. The asymmetry is not a quirk of this bank's list. A record written by people looking at data that is arriving naturally comes out this way.

ONE ELEMENT, EIGHT LINES, AND THE SEVENTH LINE IS THE ONE THAT FAILED This entry belongs to the invented bank and is the feed behind incident I10. No system, platform or supplier is named on it. DATA DICTIONARY ENTRY: THE COLLATERAL VALUATION FEED T1 The definition the assessed value of the charge securing the loan, in Rs crore T2 The source system named in the entry, and named nowhere in this guide T3 The named data owner one person in the business, by name T4 The named data steward one person in the source system, by name T5 Permitted values a positive figure in Rs crore, carried to two decimals T6 Refresh frequency every working day, before the overnight run T7 What happens when absent NOT WRITTEN T8 Lineage to the report traced from the source to the secured advances line SEVEN LINES WRITTEN. LINE T7, LEFT BLANK, IS THE ONLY ONE THAT DESCRIBES A BAD DAY.
A dictionary entry is eight lines long, and on the feed behind this bank's worst data failure the seven describing the value were all written while the one describing its absence was left blank.
Try it out

What is lineage, and what does an element without it lose?

How complete is this bank's risk data set, and what do the counts prove?

Now the measured state, and every figure here belongs to the invented Vindhya Commercial Bank Limited. One hundred and forty seven data elements feed its monthly risk report. All eight attributes are present for 42 of them, or 28.6 per cent. A named data owner, T3, is present for 103, or 70.1 per cent, so 44 elements have nobody. A rule for absence, T7, is missing for 105, or 71.4 per cent. And lineageThe traced path from where a number originates to the report line it ends up in, which is what makes it checkable., T8, is missing for 71, or 48.3 per cent.

The 28.6 per cent needs naming before it goes any further. Vindhya Commercial Bank Limited has a second 28.6 per cent that means something else entirely, and the two are the identical fraction rather than a coincidence of rounding. The 28.6 per cent counted above is data governance completeness, 42 of 147 elements carrying all eight attributes, and it is not committee independence, the 2 of the 7 bodies other than the board itself carrying an independent director. Forty two over 147 reduces exactly to 2 over 7. Both are 28.57 per cent. The two are the same number about two unrelated things, and a paper that puts them in one sentence without naming the object has built a pattern out of a coincidence.

Now put the counts against each other. Together they prove something none of them states on its own. One hundred and forty seven less the 105 missing a rule for absence is 42. And 42 is exactly the count carrying all eight attributes. An element cannot be complete without T7, so every complete element is inside the 42 that carry T7, and since both sets have 42 members they are the same set. The elements missing a rule for absence are precisely the elements that are incomplete, so every ownership gap and every lineage gap in this bank sits inside that same 105. Nothing in that conclusion is assumed. Two counts landing on the same number force it.

147 RISK DATA ELEMENTS, AND WHAT THE COUNTS PROVE ABOUT EACH OTHER Every count is the invented bank's own. One bar length here is one element, and two of the bars end at the same place. 42 105 carry all eight attributes do not carry all eight attributes T3, A NAMED DATA OWNER: PRESENT ON 103 OF 147 103 present, 44 with nobody T7, A RULE FOR ABSENCE: PRESENT ON 42 OF 147 42 present, 105 without one T8, LINEAGE TO THE REPORT LINE: PRESENT ON 76 OF 147 76 present, 71 with none 147 LESS THE 105 WITH NO RULE FOR ABSENCE = 42 AND 42 IS EXACTLY THE COUNT CARRYING ALL EIGHT so every ownership gap and every lineage gap sits inside that same 105
Two independent counts land on the same 42, which forces a conclusion neither of them states: the elements missing a rule for absence are exactly the elements that are incomplete.
Try it out

One hundred and forty seven less the 105 missing a rule for absence is 42, and 42 elements carry all eight attributes. What does that prove?

Debt Capital Markets Bootcamp — Fin Maverick

Which attribute is missing most often, and why is that the worst one to lose?

T7 is missing on 105 of the 147, which makes it the most often absent line in the record, and it is also the line that decides what happens on the worst day of the year. The two facts are related, and the relationship is not bad luck.

Think about who writes a dictionary entry and when. The entry gets written by somebody looking at data that is arriving. The value is in front of them. The writer can see its shape, its range, its format, the place it came from and where it goes. Every one of the other seven attributes can be answered by looking at what is there. T7 asks about a state the writer has never seen, so it is the only attribute that cannot be answered by looking. The rule for absence requires somebody to stop, imagine a morning when the file does not come, and decide in advance who is told, what the report shows in the meantime, whether yesterday's value may be carried forward and for how long, and at what point the number stops being publishable. Writing that line is imaginative work, it takes a conversation with people downstream, and it is the first thing dropped when a documentation exercise is running behind.

So the attribute most often missing is missing for a structural reason rather than a careless one. Nobody skipped it. T7 is simply the only line that cannot be completed by describing what is in front of the person writing it. A record that describes the value and not its absence describes only the days when everything works, and those are precisely the days on which nobody needs a record.

What does an element without lineage actually lose?

Lineage, T8, is missing on 71 elements, being 48.3 per cent, and it fails differently from the others. An element with no lineage is not wrong. The element is present, it looks entirely normal, it has a definition and a source and an owner, and it sits in the report doing its job. The one thing lost is the ability to answer a single question, and that is the only question anybody ever asks in anger: where did this come from?

The question arrives on the day a number is challenged. Somebody outside the risk function says the secured advances figure does not match what they have. Now the work begins, and with lineage recorded it is a reading exercise: follow the path, find the step where the two versions part, done in an afternoon. Without lineage it is an investigation. Somebody has to reconstruct the path from people's memories, and reconstruction is not the same as tracing. The reconstruction is built by the same people whose work is being questioned. Lineage is what turns a number from something present into something checkable, and the difference only ever shows up under challenge.

There is a household version of this too, and it is the one everybody has lived. Somebody in the household says the electricity bill has gone up. The number is right there on the bill. But where did the comparison figure come from, last year's bill, a memory, an average somebody once worked out? Without a traced path, the argument is not about electricity at all. The argument is about whose recollection is better, and an argument like that has no ending.

How many elements carry none of the three, and why is the answer a range?

Three gaps have now been counted: 44 elements with no named owner, 71 with no lineage, and 105 with no rule for absence. The previous section proved that the first two sets both sit inside the third. So a natural question follows, and it is the question anybody planning remediation asks first: how many elements are in all three, the ones with nobody accountable, no traced path and nothing defined for the morning the value does not arrive?

The record cannot say. Two sets of a fixed size cannot both fit inside a smaller container without touching, though, and that is better than a guess. Seventy one plus 44 is 115. The container is 105. Anything above the container has to be double counted, so at least 115 less 105, being 10 elements, must be in both sets. At the other end, nothing in the record stops all 44 ownership gaps sitting inside the 71 lineage gaps, so the overlap could be as high as 44. Between 10 and 44 elements carry neither an owner nor lineage nor a rule for absence, and no honest statement puts a single figure between those two.

TWO GAPS INSIDE ONE CONTAINER: THE OVERLAP HAS A FLOOR AND A CEILING Both arrangements are consistent with the invented bank's counts. Nothing in its record chooses between them. ARRANGEMENT A: THE LEAST OVERLAP THE COUNTS ALLOW THE 105 WITH NO RULE FOR ABSENCE 71 WITH NO LINEAGE 44 WITH NO OWNER 10 LACK ALL THREE ARRANGEMENT B: THE MOST OVERLAP THE COUNTS ALLOW THE 105 WITH NO RULE FOR ABSENCE 71 WITH NO LINEAGE 44 WITH NO OWNER 44 LACK ALL THREE 71 PLUS 44 IS 115, AGAINST A CONTAINER OF 105 SO AT LEAST 10 OVERLAP, AND AT MOST ALL 44 DO the record fixes the bound and not the number, and no honest statement picks a point inside it
Two gaps of fixed size squeezed into a smaller container must overlap by a computable minimum, which is why the answer here is a range with a hard floor rather than a figure somebody chose.

The range is the right answer here rather than a weak one, and the reason matters. A number would be more comfortable to put in a paper, and every number between 10 and 44 would be an invention. The counts in this bank's record fix how many elements are in each set. The counts do not record which element is in which, and joint membership cannot be recovered from separate totals. Stating the bound is the only claim the record actually supports, and picking a point inside it would be manufacturing a fact and calling it analysis. A reader who understands that will spot the same move everywhere else it is made.

Try it out

Seventy one elements lack lineage and 44 lack a named owner, and both sets sit inside the same 105. How many lack both?

Investment Banking Analyst Bootcamp — Fin Maverick

If the biggest gap were fixed everywhere, how complete would the set be?

This is the question a remediation plan actually turns on, and the arithmetic gives an answer that stops most plans in their tracks. Suppose the bank does the obvious right thing and writes a rule for absence onto every one of the 105 elements that lacks one. Writing 105 rules is a large, real job: 105 conversations with people downstream about what should happen on a morning a value does not arrive. How complete is the set when it is finished?

Start from what is inside the 105. Two counts landing on the same 42 proved that every one of the 71 lineage gaps sits inside it. So of the 105 elements missing a rule for absence, exactly 71 also have no lineage and exactly 34 do have lineage. Completeness needs all eight, so writing a rule for absence onto an element that has no lineage does not complete it. The eighth is still missing. At most 34 of the 105 can be completed by this work, so completeness rises from 42 to at most 76 of 147, being 28.6 per cent to 51.7 per cent, and then it stops dead.

Two things are worth noticing about that 76. First, it is not a modelled figure. The 76 is this bank's own 147 less its own 71, so the ceiling is a locked count rather than a projection. Second, the phrase at most is doing real work. The 34 will only all complete if each of them is missing nothing else, and the record does not say that. The honest line is the best case, and the real answer sits at or below it.

Try it out

One hundred and five of the 147 elements lack a rule for what happens when the value is absent. Before the control moves: if a rule were written onto all 105, how complete would the data set be?

Play with it

Write the missing rule onto more elements and watch the line stop

One control: n, the number of the 105 elements lacking a rule for absence that are given one, from 0 to 105. Two consequences read together: the count of elements carrying all eight attributes, and that count as a share of 147. The line drawn is the best case the counts allow, and it is labelled as one. The solved points are these. At n of 0, where this bank actually sits, 42 of 147 carry all eight, being 28.6 per cent, and that 28.6 per cent is data governance completeness and not the 2 of the 7 bodies other than the board itself carrying an independent director, a different measure that lands on the identical fraction. At n of 17 it is 59 of 147, being 40.1 per cent. At n of 32 it is 74 of 147, being 50.3 per cent, the first whole count past half. At n of 34 it is 76 of 147, being 51.7 per cent, and the line stops dead. At n of 105, the whole population fixed, it is still 76 and still 51.7 per cent. Seventy one elements have no lineage, and no amount of work on one attribute touches another, so no setting of this control reaches 147.

0 WRITTEN, WHERE THE BANK IS0 WRITTEN105 WRITTEN
BEST CASE ONLY: THE MOST FAVOURABLE ARRANGEMENT THE COUNTS ALLOW The record does not fix which element lacks which attribute, so the real answer sits at or below every line drawn here. 147 RISK DATA ELEMENTS 42 105 carries all eight attributes rule for absence written, still short of lineage still no rule for absence COMPLETENESS AS THE RULE IS WRITTEN ONTO MORE ELEMENTS 100 80 60 40 20 0 PER CENT COMPLETE 100 per cent, and no setting of this control reaches it THE CEILING: 76 OF 147, BEING 51.7 PER CENT 0 17 34 51 68 85 105 ELEMENTS GIVEN A RULE FOR ABSENCE, OUT OF THE 105 THAT LACK ONE
Rules written
0
Carry all eight
42 of 147
Completeness
28.6 per cent
Still short
105

With a rule for absence written onto 0 more elements, at most 42 of the 147 carry all eight attributes, being 28.6 per cent, and the ceiling is 76.

Educational illustration. The 147 elements, the 42 complete, the 103 with a named owner, the 105 with no rule for absence and the 71 with no lineage are Vindhya Commercial Bank Limited's own invented counts and not one of them is a requirement. Anything above 0 on the control is a setting of the dial and is not a figure from the case. The line drawn is a best case. The record fixes how many elements lack each attribute and not which element lacks which, so the most favourable arrangement consistent with the counts is the one shown and the real answer is at or below it. The line passes half of 147 at 32 rules written, being 74 elements, and stops at 34. There is no crossing at 100 per cent anywhere on this control and there cannot be one. Seventy one elements have no lineage recorded, and writing a rule for absence does not give them any.
Spotting Quality of Earnings Red Flags — free micro-course from Fin Maverick

What happened on the day the feed simply stopped arriving?

Seven attributes out of eight, and the missing one was the only one that mattered.

Month 10. The collateral valuation feed at Vindhya Commercial Bank Limited went stale for 11 working days and 340 loans were wrongly marked. Gross Rs 1.4 crore, no recovery, net Rs 1.4 crore, and no customer lost money. The stale feed is incident I10 in this bank's own loss record, and it is the incident behind the year's one material weaknessThe most severe control finding rating, used where a deficiency creates a reasonable possibility that a material misstatement goes undetected., rated D4 on the bank's own four point scale, affecting the valuation of Rs 8,640 crore of secured advances.

And here is the finding, the whole mechanism in one line. The data dictionary entry for that feed had T1 to T6 and T8, and did not have T7. Read it again slowly. The feed had a definition. The entry had a named source. The entry had a named owner and a named steward. The entry had permitted values and a stated refresh frequency. The entry even had lineage, traced all the way from the source to the report line it fed. Seven attributes out of eight, written down, in a record, before anything went wrong.

The one thing nobody had written was what should happen if the value did not arrive. So when it did not arrive, nothing was defined to happen, and nothing did. Not for one day, the kind of gap anybody might miss. For 11 working days a value sat in the report, present, correctly formatted, inside every permitted range and older than it should have been. Every check that existed passed it. Every check that existed was a check on a value that was there.

Nobody was careless here. The failure was in the design, and it is worth naming as one. Seven of the eight attributes can be answered by looking at the data in front of the writer and one of them cannot, so the people who wrote that entry did an above average job by their own institution's standard and still left out the line that would have mattered. The dictionary described a feed that works. The feed stopped working.

THE WELL DOCUMENTED FEED, AND THE ELEVEN DAYS NOBODY HAD DESCRIBED Incident I10 at the invented bank, month 10. Every figure on this drawing is the bank's own. T1 T2 T3 T4 T5 T6 T7 T8 SEVEN OF THE EIGHT WERE WRITTEN. T7, WHAT HAPPENS WHEN THE VALUE IS ABSENT, WAS NOT. WHAT WAS DEFINED TO HAPPEN: NOTHING WAS WRITTEN DOWN ELEVEN WORKING DAYS 1 2 3 4 5 6 7 8 9 10 11 the same value stood on every one of them, present, formatted and inside every permitted range THE MARKING 340 loans were wrongly marked while the stale value stood. THE LOSS Gross Rs 1.4 crore, no recovery, net Rs 1.4 crore. Nobody lost money. THE FINDING The year's one material weakness, rated D4, over Rs 8,640 crore of secured advances.
A feed carrying seven of the eight attributes still failed for eleven working days, because the attribute it lacked was the only one describing a morning when the value does not arrive.
Try it out

The collateral valuation feed had seven of the eight attributes written down. Why did that not help?

Spotting Quality of Earnings Red Flags teaches you to test whether a reported profit is a sound base to forecast from.

Had anything warned them, and what happened to the warning?

Yes, and this is the part that makes the incident worse rather than better. Four months earlier, in month 6, the same collateral valuation feed was stale for 2 working days. A data quality check caught it. The check worked exactly as a check should work: it noticed, on the second day, that a value was older than it should be, and it said so. And then nobody raised it as an issue. The month 6 staleness sits in this bank's record as near miss N3, correctly recorded, correctly described, and connected to nothing.

So the month 10 incident was not the first time this feed failed. The month 10 incident was the second, and the first had already produced, free of charge and with no loss attached, exactly the information somebody needed: this feed goes stale, the existing checks notice it, and the record has no line saying what to do next. A near miss carries the same information as a loss and costs nothing to collect, and this bank collected the information and then did not use it. The value of a near miss record is not the recording. The value is in the linking.

THE SAME FEED, TWICE, FOUR MONTHS APART Bar height is duration in working days. Both events belong to the invented bank's own record. 0 2 5 11 WORKING DAYS NEAR MISS N3 2 WORKING DAYS INCIDENT I10 11 WORKING DAYS FOUR MONTHS APART, NOTHING LINKED 1 2 3 4 5 6 7 8 9 10 11 12 MONTH OF THE YEAR THE CHECK WORKED BOTH TIMES. THE LINK BETWEEN THE TWO WAS NEVER MADE.
The same feed failed twice with the same cause, and the first failure was caught by a working check and recorded as a near miss that led to nothing, four months before the second one produced a material weakness.
Try it out

The same feed was stale for 2 working days in month 6, a check caught it, and nobody raised it. What was thrown away?

Why does a count in this bank never travel without its object?

One habit is worth carrying away from this guide, and it costs nothing. In an institution of any size, small counts and round figures repeat, and a repeated number invites a reader to see a pattern that is not there. Vindhya Commercial Bank Limited is a good example, and 42 is its most crowded number.

Forty two means five different things in this bank's records. There are 42 findings from control testing, rated on its own four point scale. There is Rs 42.0 crore of gross loss on incident I2, the settlement instruction that went out twice. There are 42 of the 147 risk data elements carrying all eight attributes, the data governance completeness count. There are 42 open issues aged beyond 90 days, being the 18 in the 91 to 180 day bucket plus the 15 in the 181 to 365 day bucket plus the 9 beyond 365 days. And there is Rs 42.0 crore of total excess of realised loss over measured value at risk across the year's seven backtesting exceptions. None of the five has anything to do with any of the others, and a sentence that carries a bare 42 has invited its reader to connect two of them.

The number 9 is just as crowded, and that is why it was named too: this bank has 9 processes numbered PR1 to PR9, 9 policies numbered PL1 to PL9, 9 letters of credit inside incident I13, 9 hours of outage in incident I9, 9 open issues aged beyond 365 days, 9 of its 42 findings carrying no stated cause, and 9 of its 16 key risk indicators sitting green. Seven objects, one number. The rule that follows is short: write the object, never the bare count.

The sharpest case is not a repeated count at all, it is an exact fraction. Forty two over 147 reduces to 2 over 7, and this bank has a genuine 2 of 7: the 2 of the 7 bodies other than the board itself carrying an independent director. Both are 28.57 per cent. One is data governance completeness and the other is committee independence, and no amount of staring at them will make them related.

ONE NUMBER, FIVE OBJECTS, AND NONE OF THEM IS ABOUT ANOTHER All five belong to the same invented bank in the same year, which is exactly why a bare count is unsafe to write. 42 findings from control testing, rated D1 to D4 on the bank's own scale Rs 42.0 crore the gross loss of incident I2, the settlement instruction sent twice 42 of the 147 risk data elements carrying all eight attributes, which is the only one of the five this guide is about 42 open issues aged beyond 90 days, being 18 plus 15 plus 9 Rs 42.0 crore of realised loss above measured value at risk, across seven exceptions 42 OVER 147 REDUCES EXACTLY TO 2 OVER 7, AND BOTH ARE 28.57 PER CENT one is data governance completeness, the other is committee independence, and they are unrelated
Five different objects in one bank in one year carry the same number, which is why every count in this guide travels with the thing it counts attached to it.

Who actually picks this up, and what do they do with it?

Four people read a data completeness measure and read it for four different things. Watching all four read it is the fastest way to see what a completeness measure is for.

The chief risk officer, Sunanda Ravikumar in this invented bank, reads it for the ceiling rather than the level. Twenty eight point six per cent complete is uncomfortable and does not by itself tell her what to do. The useful fact is a ceiling: a second gap sits underneath the first, so the largest single body of remediation available cannot take the set past 51.7 per cent. A ceiling changes the shape of a plan from one workstream to two, and it changes what she can promise a committee. The most useful question anybody can ask of a completeness figure is not how low it is, it is what the best possible outcome of the obvious fix would be.

An internal auditor, Rustom Batliwala here, reads it for lineage and nothing else. Every finding he writes will eventually be answered with a number, and every number he is given has to be traced or it is an assertion. Forty eight point three per cent of this bank's risk data elements have no traced path from source to report line. Before he starts, then, he knows that roughly half of what he is about to be shown cannot be verified without reconstructing it by hand. The 48.3 per cent is a scoping fact, and it is worth more to him than the headline.

A credit analyst at another institution, looking at this bank from the outside as a counterparty, reads it for what it implies about everything else. Such an analyst will never see this measure, so the useful move is to ask for it. A bank that can state what share of its risk data elements carries a named owner and a rule for absence has thought about the question. A bank that cannot produce the figure at all has revealed something more interesting than any figure would have. Not that it is badly run, but that the numbers on its report have never been asked where they came from.

And the household version, where the mechanism is the same at every scale. A household takes the five numbers its own month runs on and writes four lines against each: what it means exactly, where it comes from, who updates it, and what will be done in the month it does not arrive. The fourth line is the one most likely to be skipped, and it is the only line that is about a bad month. Writing the four lines takes an evening, it produces no new information, and it turns five numbers relied on into five numbers that can be checked. The bank version needs 147 entries and a measure; the household version needs a sheet of paper, and the missing line is the same line in both.

Where do the expectations on risk data actually come from?

By itself, an owner, a steward, a definition and a rule for absence bind nobody. The obligation comes from somewhere else, and naming that somewhere precisely is where confident writing usually goes wrong.

The mechanism set out above is jurisdiction free. An owner, a steward, a written definition and a rule for absence are not Indian, European or American ideas. All four are what it takes for a number to be trustworthy, and a household applying them to five figures on a sheet of paper is doing the same thing this bank is doing across 147 elements. Where jurisdiction enters is not the mechanism, it is the obligation: who is compelled to do it, to what standard, on which entities, and by when.

India

What is named here, and where the binding version lives

The idea that a bank should be able to aggregate its risk data reliably and trace a reported line back to its source is set out in the principles for risk data aggregation and risk reporting published by the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Basel principles are where the expectation originates, and they are the origin of the vocabulary used above.

A standard published in one place is not what binds a bank in another, so naming only the global standard is the confident and common error. An Indian bank's actual obligations on risk data, on the completeness and accuracy of what it reports, on outsourcing where a source system sits outside the institution, and on the governance and information security around all of it, come from the Reserve Bank of India at rbi.org.in. The reader is sent there for the text rather than given a summary of it here.

The eight attributes T1 to T8 are the invented bank's own working list and are not anybody's requirement, and every count, share and rating in this guide belongs to that invented bank. Every obligation should be confirmed at source.

Try it out

Which body publishes principles for risk data aggregation and risk reporting, and which one decides what an Indian bank must actually do?

Risk Management Program Bootcamp — Fin Maverick

What is covered separately?

What a model is, how a model inventory is built and tiered and how a validation is run are treated separately under model risk and the model inventory. Data governance picks up the data those models are fed and hands the models straight back. Whether a wrong number came from a wrong input or a wrong rule is a comparison of data risk against model risk and is settled there rather than here. The monthly risk report itself, what it carries and what a committee actually needs from it, is treated separately under risk reporting, and so are the key risk indicators and the early warning indicators that decide which of these numbers gets a colour against it. Access management, information security, the controls over a source system and the risk and control self assessment belong with the operational risk material: incident I10 and its material weakness are used here as records and the control finding is handed back. How an institution detects, contains and recovers from a failed feed belongs with the resilience material. The collateral valuation itself, the haircut, the expected loss it feeds and the secured advances line all belong with the credit and counterparty risk material and are named here rather than derived. A loan, a deposit and a balance sheet are covered separately.

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat actually binds a bank in India on risk data, on what must be reported and how completely, and on outsourcing, governance and information security where a source system sits outside the institutionrbi.org.in
Bank for International SettlementsThe Basel Committee principles for risk data aggregation and risk reporting, which are the origin of the expectation that a reported line can be traced to its sourcebis.org

Vindhya Commercial Bank Limited, Nirjhar Industries Limited, Zoya Kalbagh, Sunanda Ravikumar and Rustom Batliwala are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.